Incorrect authorization in snipe-it - #VU145091
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to modify audit log entries for assets outside their FMCS visibility and disclose limited asset-related information.
The vulnerability exists due to improper access control in asset audit endpoints when handling audit requests for target assets. A remote user can send a request targeting an asset outside their authorized FMCS scope to modify audit log entries for assets outside their FMCS visibility and disclose limited asset-related information.
This applies to installations with FMCS enabled, and exploitation requires knowledge of the target asset identifier such as an id, asset tag, or serial depending on the endpoint.